2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20638MEDIUM6.5NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.
CVE-2019-19390MEDIUM5.4The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unf...
CVE-2019-4654MEDIUM4.8IBM QRadar 7.3.0 to 7.3.3 Patch 2 does not validate, or incorrectly validates, a certificate which could allow an attack...
CVE-2019-4594MEDIUM5.9IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to obtain sensitive information, caused by the failure t...
CVE-2019-4593MEDIUM4.3IBM QRadar 7.3.0 to 7.3.3 Patch 2 generates an error message that includes sensitive information that could be used in f...
CVE-2019-2880HIGH8.8Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security...
CVE-2019-20767HIGH7.2Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor...
CVE-2019-19500MEDIUM5.4Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstra...
CVE-2019-19301HIGH7.5A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X2...
CVE-2019-19300HIGH7.5A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation...
CVE-2019-10939CRITICAL9.8A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (...
CVE-2019-14326HIGH7.8An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) ...
CVE-2019-18822HIGH8.8A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which...
CVE-2019-16879CRITICAL9.8The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentica...
CVE-2019-11480HIGH8.1The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options whe...
CVE-2019-1866LOW3.7Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker t...
CVE-2019-13916HIGH8.8An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1. As a Bluetooth Low En...
CVE-2019-7305CRITICAL9.8Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible ...
CVE-2019-18376MEDIUM5.9A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) u...
CVE-2019-18375MEDIUM6.5The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with ac...
CVE-2019-20637HIGH7.5An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does...
CVE-2019-4746MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2019-4740MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2019-4737MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2019-4603MEDIUM4.3IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now